Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-59145

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The a…

No fix yet
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-59144

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time …

No fix yet
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-50755

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

No fix yet
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.1
CVE-2026-59142

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The atta…

No fix yet
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.1
CVE-2026-59141

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The att…

No fix yet
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.1
CVE-2026-59140

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. …

No fix yet
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.1
CVE-2026-59139

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The…

Mitigation only
Fix from $2,300 2026-07-21
Openj9 CRITICAL 9.6
CVE-2026-16441

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, exec…

Fix: 0.60.0+
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2016-20096

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute ar…

No fix yet
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.6
CVE-2026-47416

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege esc…

Patch available
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.6
CVE-2026-47413

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenan…

Patch available
Fix from $2,300 2026-07-21
Openj9 CRITICAL 9.1
CVE-2026-16439

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

Fix: 0.60.0+
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-47410

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic k…

Patch available
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.4
CVE-2026-47407

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un…

Patch available
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.3
CVE-2026-64825

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any dir…

Patch available
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-47396

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authenti…

Patch available
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-47393

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.…

Patch available
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.9
CVE-2026-47392

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` i…

Patch available
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-47391

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC …

Patch available
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28321

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to esca…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28317

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administr…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28314

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28313

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28312

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28310

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a sys…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28309

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. Th…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28308

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrato…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28307

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28306

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system admi…

Fix: 2026.3+
Fix from $2,300 2026-07-21